Privacy Policy
This is a good-faith starting draft, grounded in what Northlight actually collects today — it has not been reviewed by a lawyer. GDPR carries real enforcement risk (fines up to €20M or 4% of global turnover for serious breaches), and this should be reviewed by qualified counsel before real customer data flows through it at any meaningful scale.
Who we are
Northlight (currently operating as a Swedish Enskild Firma, transitioning to Northlight Software AB) is the data controller for personal data collected through this website. We're based in Sweden.
Contact: [email protected] — placeholder, needs a real, monitored address before launch.
What we collect, and why
We only collect what you give us directly through our waitlist and inquiry forms. We don't currently use cookies, analytics, or any tracking technology on this site.
| Data | Why we collect it | Legal basis |
|---|---|---|
| Name, email | To respond to your inquiry or notify you when a product launches | Legitimate interest / consent |
| Company, phone (optional) | To understand who we're talking to and follow up appropriately | Legitimate interest |
| Your message | To understand and respond to what you're asking | Legitimate interest |
| Which page/campaign you came from | So we know which outreach is actually working — not tied to your identity beyond this | Legitimate interest |
Note on marketing consent: if you join a waitlist, we take that as consent to email you about that specific product's launch — nothing broader, and you can withdraw it any time.
How long we keep it
Default policy (placeholder, needs confirming): we retain inquiry and waitlist data for 24 months from your last contact with us, or until you ask us to delete it — whichever comes first. This hasn't been finalized as an actual company policy yet.
Where your data lives, and who sees it
Your data is stored on infrastructure hosted in the EU (France), and is not shared with, sold to, or processed by any third party. Northlight is a solo-operated company — the only person with access to this data is Northlight's owner.
Your rights under GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Restrict or object to how we process it
- Receive your data in a portable format
- Lodge a complaint with Sweden's data protection authority, Integritetsskyddsmyndigheten (IMY)
To exercise any of these, contact us at the email address above.
Cookies and future changes
This site currently uses no cookies or tracking of any kind. As we begin running ads (LinkedIn, Google) to reach potential customers, that will change, and this policy — along with a proper cookie-consent mechanism — will be updated before those go live, not after.
If you become a customer of our products
This policy covers your visit to this website — inquiries, waitlist signups, and similar. If you become a customer of a Northlight product (for example, the trucking compliance co-pilot), a separate agreement applies to the data you enter about your own drivers and vehicles. In that relationship, your company is the data controller and Northlight acts as a data processor on your behalf — a distinct legal relationship from the one this policy describes, governed by its own Data Processing Addendum presented at product signup, not by this page.
Changes to this policy
We'll update the "last updated" date above whenever this changes, and post material changes here directly.